logo

EC2 Grouper Campaign (Campaign)

ID: 51add7c6-5990-5bde-9c95-f7c8e4c88a2a

STIX ID: report--51add7c6-5990-5bde-9c95-f7c8e4c88a2a

Feed Name: Wiz Cloud Threat Landscape

Threat Score
65/100

Date Published: 2024-12-30

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

The report describes the EC2 Grouper threat actor active in cloud environments: they use AWS PowerShell tooling with distinctive (recently modified) user agents, create security groups with predictable names like `ec2group`/`ec2group12345` via `CreateSecurityGroup`, and perform automated reconnaissance (`DescribeInstanceTypes`, `DescribeRegions`, `DescribeVpcs`) followed by actions such as `RunInstances` and occasional VPC/internet-gateway creation; resource hijacking is suspected but not confirmed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.